Executive brief
The GDPR Cookie Consent plugin for WordPress, which helps websites manage legal compliance banners, contains a security flaw that allows low-level users to change administrative settings. Specifically, an attacker with a basic account (like a subscriber) can modify the schedule for when the plugin scans the website for cookies. While this does not directly expose sensitive customer data, it allows unauthorized users to interfere with administrative functions and website compliance operations.
Technical details
The GDPR Cookie Consent plugin for WordPress is vulnerable to an authorization bypass due to a missing capability check and missing nonce (CSRF) verification on the gdpr_cookie_consent_ajax_save_schedule_scan() function, which handles the wp_ajax_gcc_save_schedule_scan AJAX action. This vulnerability allows authenticated attackers with Subscriber-level permissions or higher to modify the gdpr_scan_schedule_data option. This option controls the plugin's cookie scan schedule, a function intended to be restricted to administrators with the manage_options capability. The issue is addressed in version 4.3.7.
Affected products
- wplegalpages Cookie Banner for GDPR / CCPA – WPLP Cookie Consent up to, and including, 4.3.6
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory
References
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/class-gdpr-cookie-consent-admin.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/admin/class-gdpr-cookie-consent-admin.php
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/includes/class-gdpr-cookie-consent.php
- https://plugins.trac.wordpress.org/changeset/3601475/gdpr-cookie-consent/tags/4.3.7/admin/class-gdpr-cookie-consent-admin.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ddee10e0-093c-47a3-8aa9-946d6d21e1b2?source=cve